I am using splunk 60 day free trial non-enterprise edition and created a new custom index in splunk and manually added a sample event csv format file in the new index and all date is 2 days ago sample data
splunk integration with xsoar does not generate any incident, is there a configuration and timestamp problem?
Hi @Manikandan_sam , is this the first time you are configuring the XSOAR integration with Splunk? If yes, you may want to change the First fetch timestamp to 2 or 3 days, to capture incidents that were created before. If not, please check if certain incidents were missed while others were created, and open a support case with screenshots and logs.
yes this is my first time integrating splunk
that sample log file is a data day (March 3) for testing so I loaded it into splunk add data and created a custom index
that the log file data is only from March 3rd and how to use timestamp lookup and I already use that custom query in splunk config
when i search xsoar cli !splunk-search query="index=notes" it shows index data and i can also parse the specific url and ip field in the playbook
So is this the proper method to use Splunk custom index to get all the data into xsoar?
1. Please also try encapsulating the index name as per default example when creating new instance. eg.
search `notes` | expandtoken
2. Reset timestamp - unless you know you have new data coming in or within the look back windows (15mins by default)
3. Double check you you have latest content pack installed
4. double check time on your new system (sync with NTP)
5. You can debug a test fetch with: !<instance_name>-fetch debug-mode=true
reference - xsoar.pan.dev/docs/reference/articles/troubleshooting-guide
Please let us know how you go!
thank for the replay
my custom data is from 3rd March and time also different but i uploaded it today and 2 days ago my raw file is showing in cli command but when i changed settings again it shows empty index
how to change my timestamp and get data
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!